SIGNED MARKETPLACE
Build on Vantage.
Keep the boundaries.
Curated JSON-only packages for Page, Grid, Stage, Base, and the wider Vantage workspace. Every published byte is checked against a signed catalog.
FAIL-CLOSED INSTALLATION
Vantage verifies before it installs.
Catalog signature, package SHA-256, payload SHA-256, publisher identity, type, permissions, and package signature must all match. A changed package becomes invalid automatically.
- No PowerShell, shell, or native executable payloads
- No mail credentials, license keys, tokens, or decrypted project keys
- Maximum size and path traversal protection
- Report suspicious content to the security contact
SEPARATE BY DESIGN
Shared provider. Isolated system.
Vantage Marketplace uses a private Vantage-only Backblaze B2 bucket behind its own Cloudflare Worker. It does not reuse Pace Addon Shop routes, bucket, application key, object prefix, publisher secret, accounts, or sessions.
- Dedicated
/marketplace/routes - Exact
vantage-marketplace/object prefix - Bucket-and-prefix-restricted Backblaze application key
- Independent HMAC publisher authority
Marketplace packages install inside Vantage.
Download Vantage Office 1.2.4, open Vantage Command, and choose Vantage Marketplace. The app refreshes the signed catalog automatically and falls back safely when offline.